turtleneck-review

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content such as ADRs, RFCs, and PR descriptions, which is a common vector for indirect prompt injection.
  • Ingestion points: The skill ingests user-provided architectural documents in SKILL.md.
  • Boundary markers: The instructions include a 'Boundaries' section and specific output formatting, but lack explicit data delimiters for the input documents.
  • Capability inventory: The skill is limited to generating text reviews and does not have access to tools for network communication, file writing, or command execution.
  • Sanitization: There is no evidence of input validation or sanitization for the documents being reviewed.
  • [NO_CODE]: The skill contains only markdown instructions and no executable scripts or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:43 AM
Security Audit — agent-trust-hub — turtleneck-review